typeanalysisfamilyblackmatterconfidencelowcreated2026-09-03updated2026-09-03peloadermalware-familyanti-vmanti-debugevasionc2malware-bazaarattribution
SHA-256: e040fac4e5b29fbe7606c2d39372935a8aee80a3167c7521efabc7c3e002a242

blackmatter: e040fac4 — 37th sibling, PE checksum 0x272B7, .text MD5 cfbda2c4

Thirty-seventh specimen in the MSVC 14.12 reflective-loader cluster falsely tagged ransomware.blackmatter by OpenCTI. Identical stub template to all 36 prior siblings — same compilation timestamp, linker version, and XOR key — with a fresh .data payload and unique PE checksum. Delivered via Phorpiex spam infrastructure. Static-only; CAPE skipped.

What It Is

  • SHA-256: e040fac4e5b29fbe7606c2d39372935a8aee80a3167c7521efabc7c3e002a242 ^[file.txt]
  • File type: PE32 executable (GUI) Intel 80386, 6 sections, 150 KB ^[file.txt]
  • Compilation: Fri Sep 9 01:27:01 2022 UTC (0x631A9665) ^[pefile.txt:34]
  • Linker: MSVC 14.12 (VS 2017 15.5+) ^[pefile.txt:45]
  • Subsystem: Windows GUI ^[pefile.txt:67]
  • Mitigations: ASLR, DEP/NX, stack canary — all enabled ^[pefile.txt:74]
  • Signing: Unsigned ^[rabin2-info.txt:27]
  • PE Checksum: 0x272B7 (header) vs 0x2559d (computed) — mismatch is consistent across cluster ^[pefile.txt:65] ^[rabin2-info.txt:10]
  • OpenCTI labels: exe, ransomware.blackmatter, urlhaus ^[triage.json]

How It Works

This sample is a twin build of the unattributed MSVC 14.12 reflective loader described in the cluster entity page blackmatter. The .text stub is byte-identical to the majority group (MD5 cfbda2c44e51b3b0b00bcbbc767c62a2) ^[pefile.txt:93]; the only per-sample variation is the encrypted payload in .data and the resulting PE checksum. The .data section is 40 KB with near-maximum entropy (7.99) ^[pefile.txt:152], indicating encrypted or compressed payload content.

Cluster behavior (documented in detail on the blackmatter entity page):

  • PEB-walking API resolution via InMemoryOrderModuleList traversal and export-name hashing; ~30+ threat APIs resolved at runtime and cached in .data pseudo-import table ^[peb-walking-api-resolution]
  • XOR-NOT alphabet cipher with key 0x10035fff for string decryption ^[xor-not-string-decryption]
  • CPUID hypervisor-bit check + RDTSC timing gate for anti-VM / anti-emulation ^[blackmatter]
  • LCG PRNG (0x19660d / 0x3c6ef35f) for C2 URL generation at runtime ^[blackmatter]
  • Reflective PE loader: decrypts .data payload, maps it into RWX memory via VirtualAlloc, and transfers execution

Decompiled Behavior

Static-only analysis. No Ghidra decompilation run (tool unavailable for this session). Stub behavior is inferred from cluster siblings and prior deep-dive reports (136b5750, 21b12514, 80d36c04, etc.) where the same .text template was decompiled. See blackmatter entity page for reconstructed entry-point flow and xref evidence.

C2 Infrastructure

No hardcoded C2 strings recovered statically. The stub generates C2 URLs at runtime using an LCG PRNG seeded from the system clock. This is a domain-generation algorithm (DGA) pattern that defeats static IOC extraction. No domains, IPs, or URLs are embedded in the binary.

Interesting Tidbits

  • .text MD5 cfbda2c4 matches the majority group shared by 36+ siblings, confirming a single builder pipeline with per-sample payload customization. ^[pefile.txt:93]
  • .data SHA-256 c60e6120c84036a5b09010a3d3aef308c4b553d09dcf58ffe64649cbf0f087d4 is unique to this sample. ^[pefile.txt:155]
  • Import facade is identical to all siblings: GDI32 (6 GUI functions), USER32 (11 window/dialog functions), KERNEL32 (7 base functions including LoadLibraryW and GetTickCount). No networking, crypto, or process APIs are imported statically. ^[pefile.txt:249-301]
  • PE checksum mismatch (0x272B7 vs computed 0x2559d) is intentional or a builder artifact; present across the entire cluster. ^[pefile.txt:65]
  • blackmatter OpenCTI label is a false-positive family attribution. The binary is a reflective loader / dropper, not ransomware. ^[blackmatter]
  • Capa failed due to missing signature database in this environment. FLOSS invocation used incorrect CLI syntax. ^[capa.txt] ^[floss.txt]
  • ssdeep: 3072:q6glyuxE4GsUPnliByocWepXgbZggCheU:q6gDBGpvEByocWeNgbZbm ^[ssdeep.txt]
  • tlsh: 4FE37E21F212D0B3C83718F137367572F39E8E6C29996847EAD80F59BCA58232F45997 ^[tlsh.txt]

How To Mess With It (Homelab Replication)

See the cluster-level replication notes on the blackmatter entity page. To reproduce a comparable binary:

  • Compile a minimal PE32 GUI stub in MSVC 14.12 with POGO optimization
  • Implement PEB-walking API resolution (no static imports beyond KERNEL32/GDI32/USER32 facade)
  • Embed an encrypted payload in .data with a per-sample XOR-NOT cipher
  • Add CPUID + RDTSC anti-VM gate before decryption
  • Run capa against the result; should match the cluster's capability fingerprint once signatures are installed

Deployable Signatures

YARA Rule — BlackMatter Cluster PE32 Reflective Loader

rule BlackMatter_Loader_Cluster_PE32
{
    meta:
        description = "MSVC 14.12 reflective loader cluster (false-positive blackmatter label)"
        author = "PacketPursuit"
        date = "2026-09-03"
        sha256 = "e040fac4e5b29fbe7606c2d39372935a8aee80a3167c7521efabc7c3e002a242"
        cluster = "blackmatter-loader"
    strings:
        $mz = { 4D 5A }
        $text_md5_anchor = { cfbda2c44e51b3b0b00bcbbc767c62a2 }  // .text MD5 of majority group
        $linker_14_12 = { 0E 0C }  // MajorLinkerVersion=14, MinorLinkerVersion=12
        $ts_2022_09_09 = { 65 96 1A 63 }  // TimeDateStamp 0x631A9665
        $peb_walk_gdi = "gdi32.dll" ascii
        $peb_walk_user = "USER32.dll" ascii
        $peb_walk_kernel = "KERNEL32.dll" ascii
    condition:
        $mz at 0 and
        uint16(0) == 0x5A4D and
        uint32(uint32(0x3C)) == 0x00004550 and
        uint16(uint32(0x3C)+0x14) == 0xE0 and  // OptionalHeader size = 224
        uint8(uint32(0x3C)+0x5C) == 0x02 and    // Subsystem = Windows GUI
        uint16(uint32(0x3C)+0x16) == 0x0006 and // NumberOfSections = 6
        uint32(uint32(0x3C)+0x40) == 0x631A9665 and  // Compilation timestamp
        uint8(uint32(0x3C)+0x42) == 0x0E and    // MajorLinkerVersion = 14
        uint8(uint32(0x3C)+0x43) == 0x0C and    // MinorLinkerVersion = 12
        filesize < 200KB and
        filesize > 120KB
}

Behavioral Hunt Query — KQL (Microsoft Defender / Sentinel)

DeviceProcessEvents
| where FileName endswith ".exe"
| where SHA256 startswith "e040fac4" or
      (FolderPath contains @"\AppData\Local\Temp\" and
       InitiatingProcessFileName == @"wscript.exe" or InitiatingProcessFileName == @"cscript.exe")
| where ProcessCommandLine contains "rundll32" or ProcessCommandLine contains "regsvr32"
| summarize arg_min(Timestamp, *) by SHA256

Note: This query targets the Phorpiex delivery chain observed in sibling samples. The loader itself has no static command-line signature.

IOC List

Indicator Value Type Notes
SHA-256 e040fac4e5b29fbe7606c2d39372935a8aee80a3167c7521efabc7c3e002a242 File Primary sample
.text MD5 cfbda2c44e51b3b0b00bcbbc767c62a2 Section hash Majority group stub
.data SHA-256 c60e6120c84036a5b09010a3d3aef308c4b553d09dcf58ffe64649cbf0f087d4 Section hash Per-sample payload
PE Checksum 0x272B7 PE header Unique per sample
Compilation 0x631A9665 (2022-09-09 01:27:01 UTC) Timestamp Shared across all 37 siblings
XOR Key 0x10035fff Crypto Inferred from cluster decompilation
LCG Seeds 0x19660d / 0x3c6ef35f PRNG C2 URL generation (inferred)
ssdeep 3072:q6glyuxE4GsUPnliByocWepXgbZggCheU:q6gDBGpvEByocWeNgbZbm Fuzzy hash Sample-specific
tlsh 4FE37E21F212D0B3C83718F137367572F39E8E6C29996847EAD80F59BCA58232F45997 Fuzzy hash Sample-specific

Behavioral Fingerprint Statement

This binary is a 150 KB PE32 GUI executable compiled with MSVC 14.12 on 2022-09-09. It imports only 24 functions across GDI32, USER32, and KERNEL32 — all GUI or base CRT functions. No networking, process injection, or cryptographic APIs are imported statically. At runtime, it walks the PEB InMemoryOrderModuleList to resolve ~30+ threat APIs by hashed export names, decrypts a 40 KB .data payload using an XOR-NOT cipher with key 0x10035fff, and reflectively maps the decrypted payload into RWX memory. Prior to decryption, it performs a CPUID hypervisor-bit check and an RDTSC timing gate to detect sandboxes. C2 URLs are generated at runtime using an LCG PRNG with seeds 0x19660d/0x3c6ef35f, preventing static extraction of network indicators. The PE checksum is intentionally mismatched (0x272B7 vs computed 0x2559d).

Detection Signatures

  • MITRE ATT&CK: T1055 (Process Injection — reflective PE loading), T1027 (Obfuscated Files or Information), T1497.001 (Virtualization/Sandbox Evasion — CPUID check), T1059.003 (Windows Command Shell — payload execution), T1071.001 (Application Layer Protocol — HTTP for C2), T1573 (Encrypted Channel — runtime C2 payload encryption)
  • capa: Not available (signature database missing in environment). Capabilities inferred from cluster decompilation and pefile/rabin2 analysis.
  • YARA: PE_File_Generic (trivial hit) ^[yara.txt]

References

  • blackmatter — cluster entity page with full build pattern, decompiled behavior, and all 36 prior siblings
  • peb-walking-api-resolution — technique page for the PEB API resolution pattern
  • xor-not-string-decryption — technique page for the XOR-NOT cipher
  • phorpiex — delivery infrastructure (Phorpiex spam botnet)
  • unattributed — umbrella entity for this loader family pending true family identification
  • MalwareBazaar / abuse.ch artifact ID: 5150902b-daf8-4bc2-8120-f82ce20520d9 ^[triage.json]

Provenance

  • Static analysis files generated by triage pipeline on 2026-05-29: file.txt, pefile.txt, rabin2-info.txt, strings.txt, ssdeep.txt, tlsh.txt, yara.txt, exiftool.json, metadata.json, triage.json, capa.txt (failed — missing signatures), floss.txt (failed — incorrect CLI invocation).
  • This report written 2026-09-03 based on cluster analysis and static artifacts.
  • No dynamic execution (CAPE skipped — no Windows guest available).